Incorrect authorization in XWiki platform - CVE-2023-50732
Published: December 19, 2023 / Updated: May 5, 2026
XWiki platform
Detailed vulnerability description
The vulnerability allows a remote attacker to execute a Velocity script without script right.
The vulnerability exists due to incorrect authorization in the document tree macro when rendering the document tree. A remote attacker can create a document with a crafted title containing Velocity code to execute a Velocity script without script right.